PT-2020-13680 · Vmware · Harbor

Hidde Smit

·

Published

2020-09-29

·

Updated

2024-08-21

·

CVE-2020-13794

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harbor versions 1.9.* through 2.0.*
Description The issue allows exposure of sensitive information to an unauthorized actor. Authenticated users can exploit an enumeration vulnerability in Harbor. The vulnerability is present in the "/users" API endpoint, which is supposed to be restricted to administrators. This restriction can be bypassed, and information can be obtained via the "search" functionality. Non-administrator users can list all usernames and user IDs by sending a GET request to "/api/users/search" with the parameter username and value .
Recommendations For Harbor versions 1.9.* through 2.0.*, update to either version 2.1.0 or 2.0.3 to fix this issue immediately. As a temporary workaround is not available, updating to the patched version is the recommended course of action.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-HARBOR-2020-13794
CVE-2020-13794
GHSA-Q9P8-33WC-H432
GO-2022-0865

Affected Products

Harbor